CISA: Ivanti Vulns Chained Together in Cyberattack Onslaught
ID: ea757883-ce7a-5b1b-8be0-b3bcc0560bb0
STIX ID: report--ea757883-ce7a-5b1b-8be0-b3bcc0560bb0
Feed Name: Dark Reading
Date Published: 2025-01-23
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
CISA and the FBI warn that threat actors are chaining several Ivanti Cloud Service Appliance vulnerabilities (including CVE-2024-8963, CVE-2024-9379, CVE-2024-8190, and CVE-2024-9380) to achieve admin bypass, SQL injection and remote code execution, enabling credential theft and web shell deployment; agencies recommend upgrading to the latest Ivanti CSA, using published IoCs and detection methods to search for compromise, quarantining/reimaging affected hosts, rotating credentials, and reporting incidents to CISA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
